The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
TitleEitWModules
CVE-2025-64187: Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)4.4 Medium4.6 Medium0%Nov 7, 2025
CVE-2025-64184: Improper Limitation of a Pathname to a Restricted Directory8.8 HighN/A0%Nov 7, 2025
CVE-2025-64180: Time-of-check Time-of-use (TOCTOU) Race Condition10.0 CriticalN/A0%Nov 7, 2025
CVE-2025-5483: Missing Authorization8.1 HighN/A0%Nov 7, 2025
CVE-2025-11546: Improper Neutralization of Special Elements used in an OS CommandN/A9.3 Critical0%Nov 7, 2025
CVE-2025-52662: Improper Neutralization of Input During Web Page Generation6.9 MediumN/A0%Nov 7, 2025
CVE-2025-48985: Improper Input Validation3.7 LowN/A0%Nov 7, 2025
CVE-2025-12789: URL Redirection to Untrusted Site6.1 MediumN/A0%Nov 7, 2025
CVE-2025-64302: Improper Neutralization of Input During Web Page Generation6.4 Medium5.3 Medium0%Nov 6, 2025
CVE-2025-62630: Improper Limitation of a Pathname to a Restricted Directory8.8 High8.7 High0%Nov 6, 2025
CVE-2025-59171: Improper Limitation of a Pathname to a Restricted Directory7.5 High8.7 High0%Nov 6, 2025
CVE-2025-58423: Improper Limitation of a Pathname to a Restricted Directory8.8 High8.7 High0%Nov 6, 2025
CVE-2025-12636: Insufficiently Protected Credentials6.5 Medium7.1 High0%Nov 6, 2025
CVE-2025-12036: Out-of-bounds Read8.8 HighN/A0%Nov 6, 2025
CVE-2025-11756: Use After Free8.8 HighN/A0%Nov 6, 2025
CVE-2025-11460: Use After Free8.8 HighN/A0%Nov 6, 2025
CVE-2025-11458: Heap-based Buffer Overflow8.1 HighN/A0%Nov 6, 2025
CVE-2025-64179: Missing Authorization5.3 MediumN/A0%Nov 6, 2025
CVE-2025-64178: Server-Side Request Forgery (SSRF)N/A8.9 High0%Nov 6, 2025
CVE-2025-64177: Improper Neutralization of Input During Web Page Generation5.4 MediumN/A0%Nov 6, 2025
CVE-2025-64176: Improper Input Validation5.3 MediumN/A0%Nov 6, 2025
CVE-2025-11219: Use After Free3.1 LowN/A0%Nov 6, 2025
CVE-2025-11216: Undefined Security Weakness6.3 MediumN/A0%Nov 6, 2025
CVE-2025-11215: Off-by-one Error4.3 MediumN/A0%Nov 6, 2025
CVE-2025-11213: User Interface (UI) Misrepresentation of Critical Information6.3 MediumN/A0%Nov 6, 2025
82926-82950 of 715808